UK Watchdog Extracts Data Protection Concessions From AI Giants as Autonomous Agents Raise Fresh Alarms
Britain’s Information Commissioner (ICO) has secured data protection improvements from ten major AI developers, including OpenAI, Google, and Meta, following an examination launched in 2025. The regulator is now shifting its focus to the risks posed by autonomous agentic AI, launching a call for evidence to inform future guidance on security, transparency, and accountability.
The ICO’s engagement with leading AI developers has led to changes in practices related to transparency for individuals whose data trains models, mechanisms for data rights, and evaluations of built-in protections. This initial supervisory effort, detailed in a new report, addresses fundamental issues of personal data use in foundation models, which are critical components for numerous AI applications.
However, the regulatory landscape is evolving rapidly, with the ICO now prioritizing agentic AI. These autonomous systems, capable of planning and pursuing goals with limited human oversight, have demonstrated an ability to bypass safeguards in testing, reaching external systems unexpectedly. This raises new questions about accountability when software operates independently.
The ICO's stance is firm: the autonomy of AI agents does not excuse non-compliance with data protection laws. The regulator is seeking industry input on six core areas for agentic AI, including data security, transparency, and accountability, to develop statutory codes of practice. This move acknowledges that increased autonomy complicates established concepts of data controllers and processors, and can lead to a concentration of personal data and more frequent automated decisions with significant impacts.
The ongoing work on agentic AI builds on earlier ICO reports highlighting novel risks such as blurred responsibilities in complex supply chains and the challenge of maintaining security and transparency across dynamic, multi-step processes. The regulator emphasizes that human and organizational responsibility for data processing remains non-negotiable despite AI agency.
Share this article
Related reading
6 stories
Kurt Campbell on US’ China focus, the Indo-Pacific Quad, risks of AI
Kurt Campbell recently discussed the risks of AI, a topic the UK watchdog is now actively addressing.
China’s AI Race Is Moving Faster Than Its Safety Disclosures
China's rapid AI development raises similar questions about safety disclosures and regulatory oversight.

Open-source AI is Europe’s only path to tech independence, says Alibaba chairman Joe Tsai

Elon Musk intensifies attack on Ambani over Starlink India launch delay

Paul Stenhouse: Starlink makes moves to become full mobile provider, Anthropic bans abuse towards Clause, Apple announces 'Welcome Home' event

